Overview
overview
10Static
static
10.rsync/a/a
ubuntu-18.04-amd64
7.rsync/a/a
debian-9-armhf
7.rsync/a/a
debian-9-mips
7.rsync/a/a
debian-9-mipsel
7.rsync/a/anacron
ubuntu-22.04-amd64
6.rsync/a/cron
ubuntu-22.04-amd64
1.rsync/a/run
ubuntu-18.04-amd64
3.rsync/a/run
debian-9-armhf
3.rsync/a/run
debian-9-mips
3.rsync/a/run
debian-9-mipsel
3.rsync/a/stop
ubuntu-18.04-amd64
6.rsync/a/stop
debian-9-armhf
6.rsync/a/stop
debian-9-mips
6.rsync/a/stop
debian-9-mipsel
6.rsync/c/go
ubuntu-18.04-amd64
3.rsync/c/go
debian-9-armhf
3.rsync/c/go
debian-9-mips
3.rsync/c/go
debian-9-mipsel
3.rsync/c/golan
ubuntu-18.04-amd64
1.rsync/c/golan
debian-9-armhf
1.rsync/c/golan
debian-9-mips
1.rsync/c/golan
debian-9-mipsel
1.rsync/c/l...c.so.6
ubuntu-22.04-amd64
.rsync/c/l...l.so.2
ubuntu-24.04-amd64
1.rsync/c/l...s.so.2
ubuntu-22.04-amd64
1.rsync/c/l...s.so.2
ubuntu-24.04-amd64
1.rsync/c/l...d.so.0
ubuntu-24.04-amd64
.rsync/c/l....23.so
ubuntu-24.04-amd64
1.rsync/c/l...v.so.2
ubuntu-24.04-amd64
1.rsync/c/lib/32/tsm
ubuntu-24.04-amd64
1.rsync/c/l...c.so.6
ubuntu-22.04-amd64
1.rsync/c/l...l.so.2
ubuntu-24.04-amd64
1Analysis
-
max time kernel
11s -
platform
debian-9_mips -
resource
debian9-mipsbe-20240418-en -
resource tags
arch:mipsimage:debian9-mipsbe-20240418-enkernel:4.9.0-13-4kc-maltalocale:en-usos:debian-9-mipssystem -
submitted
28-06-2024 12:54
Behavioral task
behavioral1
Sample
.rsync/a/a
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral2
Sample
.rsync/a/a
Resource
debian9-armhf-20240611-en
Behavioral task
behavioral3
Sample
.rsync/a/a
Resource
debian9-mipsbe-20240611-en
Behavioral task
behavioral4
Sample
.rsync/a/a
Resource
debian9-mipsel-20240418-en
Behavioral task
behavioral5
Sample
.rsync/a/anacron
Resource
ubuntu2204-amd64-20240522.1-en
Behavioral task
behavioral6
Sample
.rsync/a/cron
Resource
ubuntu2204-amd64-20240611-en
Behavioral task
behavioral7
Sample
.rsync/a/run
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral8
Sample
.rsync/a/run
Resource
debian9-armhf-20240611-en
Behavioral task
behavioral9
Sample
.rsync/a/run
Resource
debian9-mipsbe-20240418-en
Behavioral task
behavioral10
Sample
.rsync/a/run
Resource
debian9-mipsel-20240611-en
Behavioral task
behavioral11
Sample
.rsync/a/stop
Resource
ubuntu1804-amd64-20240508-en
Behavioral task
behavioral12
Sample
.rsync/a/stop
Resource
debian9-armhf-20240611-en
Behavioral task
behavioral13
Sample
.rsync/a/stop
Resource
debian9-mipsbe-20240418-en
Behavioral task
behavioral14
Sample
.rsync/a/stop
Resource
debian9-mipsel-20240226-en
Behavioral task
behavioral15
Sample
.rsync/c/go
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral16
Sample
.rsync/c/go
Resource
debian9-armhf-20240418-en
Behavioral task
behavioral17
Sample
.rsync/c/go
Resource
debian9-mipsbe-20240611-en
Behavioral task
behavioral18
Sample
.rsync/c/go
Resource
debian9-mipsel-20240418-en
Behavioral task
behavioral19
Sample
.rsync/c/golan
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral20
Sample
.rsync/c/golan
Resource
debian9-armhf-20240418-en
Behavioral task
behavioral21
Sample
.rsync/c/golan
Resource
debian9-mipsbe-20240611-en
Behavioral task
behavioral22
Sample
.rsync/c/golan
Resource
debian9-mipsel-20240418-en
Behavioral task
behavioral23
Sample
.rsync/c/lib/32/libc.so.6
Resource
ubuntu2204-amd64-20240611-en
Behavioral task
behavioral24
Sample
.rsync/c/lib/32/libdl.so.2
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral25
Sample
.rsync/c/lib/32/libnss_dns.so.2
Resource
ubuntu2204-amd64-20240611-en
Behavioral task
behavioral26
Sample
.rsync/c/lib/32/libnss_files.so.2
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral27
Sample
.rsync/c/lib/32/libpthread.so.0
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral28
Sample
.rsync/c/lib/32/libresolv-2.23.so
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral29
Sample
.rsync/c/lib/32/libresolv.so.2
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral30
Sample
.rsync/c/lib/32/tsm
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral31
Sample
.rsync/c/lib/64/libc.so.6
Resource
ubuntu2204-amd64-20240611-en
Behavioral task
behavioral32
Sample
.rsync/c/lib/64/libdl.so.2
Resource
ubuntu2404-amd64-20240523-en
General
-
Target
.rsync/a/run
-
Size
215B
-
MD5
5b63cdc5b5ceef5bde4a2f9672f68069
-
SHA1
7491fe2657c4fa2a8d99fcd7a56e38624ff8b7fc
-
SHA256
cf4aaf185449bb639ec7e7fab66583488c79526bff02c08154190c66c2cd31b3
-
SHA512
e32275e3e15c824c854329401aaece0a0456535ecdb2b296df12ef18f31613cff183fbd4279331014bc332d42f1b8c54e97aecd9029ee70d240c2468851d4551
Malware Config
Signatures
-
Writes file to tmp directory 2 IoCs
Malware often drops required files in the /tmp directory.
Processes:
rundescription ioc process File opened for modification /tmp/.rsync/a/dir.dir run File opened for modification /tmp/.rsync/a/bash.pid run
Processes
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
/tmp/.rsync/a/bash.pidFilesize
1B
MD568b329da9893e34099c7d8ad5cb9c940
SHA1adc83b19e793491b1c6ea0fd8b46cd9f32e592fc
SHA25601ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b
SHA512be688838ca8686e5c90689bf2ab585cef1137c999b48c70b92f67a5c34dc15697b5d11c982ed6d71be1e1e7f7b4e0733884aa97c3f7a339a8ed03577cf74be09
-
/tmp/.rsync/a/dir.dirFilesize
14B
MD5b3d878adcf4672bbd1f31cffac10c769
SHA1ce5798837933ece35a7e26a0a3dc06cab19c6275
SHA256ea5fce19c5fbbbc6c3c36eb9e8e295dfb525e9669aafaf8abe9ddb4e00e345c7
SHA512019d21a618b3ccc70c0c7ede225cbbb704e2b448048586c44c74c81a747129da9f3f9675f2a29363af320d2684974a1ff00ac608c53de4458aeacd3ed4f9da2c